- Remove-NTFSAccess and Remove-NTFSAudit with -RemoveSpecific are tested
also with -Path, not only with -SecurityDescriptor.
- Copy-Item2 and Move-Item2 name the destination of a folder in their
verbose message, not only of a file.
- The Enable-Privileges count compares with the privileges of the token,
so that it passes as a basic user, whose token holds one; the tests of
-PassThru restore the privilege states that they found.
- The type name comparison of Get-FileHash2 is exact, the inherited-entry
counts must be greater than zero, and the braces test (#3) checks the
verbose message that raised the FormatException.
- Remove-TestSandbox removes paths longer than 260 characters in Windows
PowerShell, through the \\?\ prefix and rd, so the long-path test of
Test-Path2 no longer cleans up itself; after a failed setup, it returns
instead of stopping AfterAll with a binding error.
Not reachable by a test: a second path whose SACL read fails while the
Security privilege is enabled; a declined -Confirm takes the code path of
-WhatIf. The tests that need a session without privileges get the CI run
as a basic user.
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Co-authored-by: AI Assistant <ai@example.com>
- #41: for the root of a drive, the cmdlets read and changed the security
descriptor of the drive, a device object. FileSystemSecurity2 now routes
drive roots through the path-based AlphaFS methods, which keep the
trailing backslash; the removal and inheritance helpers use it too.
- #109: Add-, Remove-, and Clear-NTFSAudit report a security descriptor
without the audit entries like Get-NTFSAudit, through one helper, and
Get-NTFSEffectiveAccess names the cause that Windows reported instead
of a missing Security privilege.
- #108: Copy-Item2 and Move-Item2 check the destination only for an
operation that runs; with -WhatIf, a verbose message names the conflict.
- #111: Disable-Privileges skips the privileges that the token doesn't
hold, the privilege messages are spelled right, and Get-FileHash2
declares the type name of its objects; 05-Releasing.md documents the
release metadata tests.
- rc3 review leftovers: Remove-NTFSAudit writes nothing for an item
without a SACL, the owner retry of Set-NTFSSecurityDescriptor restores
the previous owner in a finally block and keeps an owner that the
descriptor sets, and FileSystemSecurity2.Write with another item writes
only the sections that were read.
Each fix has a test that failed first, in Windows PowerShell 5.1 and
PowerShell 7; writing a drive root was checked once on a temporary VHD.
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Co-authored-by: AI Assistant <ai@example.com>
Mark the Set-NTFSInheritance change as breaking and warn that scripts that
used it to drop the inherited access entries now leave broader access in
place. Report any failure to create the hash algorithm as
HashAlgorithmNotAvailable, assert that error ID, check that the
MACTripleDES warning appears once, and guard the descriptor test.
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Co-authored-by: AI Assistant <ai@example.com>
The privilege cmdlets declared a public Path property that was never a
parameter, and Remove-Item2 declared a filter field that nothing read.
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Co-authored-by: AI Assistant <ai@example.com>
Defect 22:
- [OutputType]: Test-Path2 writes System.Boolean, not file objects;
Get-FileHash2 writes the file object with Hash and Algorithm, not access
rules; Add-NTFSAudit and Remove-NTFSAudit write audit entries since
defect 6; Copy-Item2, Move-Item2, Remove-Item2, and the five inheritance
cmdlets with -PassThru declared no type.
- Enable-Privileges and Disable-Privileges with -PassThru wrote the
privileges as one collection; they now enumerate it.
- New-NTFSSymbolicLink -PassThru returned a FileInfo for a link to a
folder; it now returns a DirectoryInfo.
The OUTPUTS sections of the pages name the same types.
Tests/OutputTypes.Tests.ps1 (new): 15 tests; Disable-Privileges and the
symbolic link need privileges and run in CI.
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Co-authored-by: AI Assistant <ai@example.com>